PT-2026-107100 · Pypi · Hydra
CVE-2026-106439
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hydra versions 1.3.4 through 1.3.6
Hydra versions 1.4.0.dev1 through 1.4.0.dev9
Description
Hydra stores legacy instantiate target blocklists and related execution-policy collections in mutable module-level state. An attacker controlling multiple sibling target entries can resolve
hydra. internal.target policy.UNCONTROLLED EXECUTION TARGETS.discard through the instantiate() function to remove a denied target. Because sibling nodes are processed in insertion order against the same modified policy, the attacker can then invoke that target. This mutation persists in process-global state and can enable code execution with the application's privileges. A narrow execution whitelist supplied by trusted Python code is not bypassed by this direct mutation path.Recommendations
Update Hydra to version 1.3.7.
Update Hydra to version 1.4.0.dev10.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hydra